Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-0549SQL Injection in Oracle Database Server

7 documents5 sources
Severity
7.5HIGHNVD
CNA10.0
EPSS
1.1%
top 21.62%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 4
Latest updateMay 1

Description

SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB05 from the January 2006 CPU, in which case this

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-ff55-4qfm-2hmv: SQL injection vulnerability in the SYS2022-05-01
CVEList
CVE-2006-0549: SQL injection vulnerability in the SYS2006-02-04

💥Exploits & PoCs

2
Exploit-DB
Oracle 9i/10g DBMS_METADATA.GET_DDL - SQL Injection (2)2007-02-26
Exploit-DB
Oracle 9i/10g - DBMS_METADATA.GET_DDL SQL Injection2007-02-23

💬Community

2
Bugzilla
CVE-2006-1494 PHP tempname open_basedir issue2006-07-03
Bugzilla
CVE-2005-2933 imap buffer overflow2006-05-03
CVE-2006-0549 — SQL Injection in Oracle Database Server | cvebase